CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,674 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
207,309 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2001-1184 EXP | wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00… | Patch early | 5.0 medium | 3.5% | 2001-12-08 |
| CVE-2006-2226 EXP | Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of service via a long argument to the… | Patch early | 5.0 medium | 3.5% | 2006-05-05 |
| CVE-2014-8653 EXP | Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOS… | Patch early | 4.3 medium | 3.5% | 2014-11-06 |
| CVE-2014-9522 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.5% | 2015-01-05 |
| CVE-2019-6263 EXP | An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS. | Patch early | 4.8 medium | 3.5% | 2019-01-16 |
| CVE-2014-9258 EXP | SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via… | Patch early | 6.5 medium | 3.5% | 2014-12-19 |
| CVE-2003-0400 EXP | Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of… | Patch early | 5.0 medium | 3.5% | 2003-06-30 |
| CVE-2015-7902 EXP | Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified… | Patch early | 5.0 medium | 3.5% | 2015-10-28 |
| CVE-2002-0918 EXP | CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails… | Patch early | 5.0 medium | 3.5% | 2002-10-04 |
| CVE-2007-3333 EXP | Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal c… | Patch early | 6.9 medium | 3.5% | 2007-07-26 |
| CVE-2006-6651 EXP | Race condition in W29N51.SYS in the Intel 2200BG wireless driver 9.0.3.9 allows remote attackers to cause memory corruption and execute arbitrary code… | Patch early | 6.8 medium | 3.5% | 2006-12-20 |
| CVE-2014-10035 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject arbitrary web sc… | Patch early | 4.3 medium | 3.5% | 2015-01-13 |
| CVE-2006-3836 EXP | Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to re… | Patch early | 5.0 medium | 3.5% | 2006-07-25 |
| CVE-2009-1768 EXP | Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 5.0 medium | 3.5% | 2009-05-22 |
| CVE-2005-3571 EXP | PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (… | Patch early | 5.0 medium | 3.5% | 2005-11-16 |
| CVE-2008-5698 EXP | HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an inva… | Patch early | 4.3 medium | 3.5% | 2008-12-22 |
| CVE-2009-0307 EXP | Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Re… | Patch early | 4.3 medium | 3.5% | 2009-04-22 |
| CVE-2007-4369 EXP | Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file… | Patch early | 5.0 medium | 3.5% | 2007-08-15 |
| CVE-2002-0680 EXP | Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a ..… | Patch early | 5.0 medium | 3.5% | 2002-07-23 |
| CVE-2014-9179 EXP | Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbit… | Patch early | 4.0 medium | 3.5% | 2014-12-02 |
| CVE-2004-2005 EXP | Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long… | Patch early | 5.1 medium | 3.5% | 2004-05-06 |
| CVE-2012-4773 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administ… | Patch early | 6.8 medium | 3.5% | 2012-10-22 |
| CVE-2002-0708 EXP | Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via a… | Patch early | 5.0 medium | 3.5% | 2002-10-10 |
| CVE-2014-8677 EXP | The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing databas… | Patch early | 5.3 medium | 3.5% | 2017-08-31 |
| CVE-2008-2748 EXP | Skulltag 0.97d2-RC2 and earlier allows remote attackers to cause a denial of service (daemon hang) via a series of long, malformed connect packets, re… | Patch early | 5.0 medium | 3.5% | 2008-06-18 |
| CVE-2015-6945 EXP | Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary web script or HTML via the bd pa… | Patch early | 4.3 medium | 3.5% | 2015-09-15 |
| CVE-2008-0388 EXP | SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user paramete… | Patch early | 6.8 medium | 3.5% | 2008-01-23 |
| CVE-2007-6187 EXP | Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote attackers to read arbitrary file… | Patch early | 5.0 medium | 3.5% | 2007-11-30 |
| CVE-2008-0265 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers t… | Patch early | 4.3 medium | 3.5% | 2008-01-15 |
| CVE-2007-3479 EXP | Stack-based buffer overflow in PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to execute arbitrary code via a long string in the… | Patch early | 6.8 medium | 3.5% | 2007-06-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt